Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
–

2087 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.5)0.32%—Dell Repository ManagerAI16/9/202617/9/2026
Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
AplazadaMedia (5.3)0.39%—NI Woocommerce Sales ReportAI16/9/202617/9/2026
The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated users to retrieve WooCommerce order details and customer contact information, to target an individual order, and to search the store's…
AplazadaAlta (8.6)0.45%—NI Woocommerce Sales ReportAI16/9/202617/9/2026
The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.
Pendiente de análisisAlta (8.8)0.42%—Oracle Demand Signal RepositoryAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.…
AplazadaAlta (8.8)0.42%—Oracle E-business SuiteAIOracle Report ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Report Manager. Successful attacks…
Pendiente de análisisAlta (7.1)0.36%—Oracle Report ManagerAIOracle E-business SuiteAI15/9/202616/9/2026
Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Report Manager. Successful attacks…
AplazadaAlta (8.8)0.42%—Oracle E-business SuiteAIOracle Report ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Report Manager. Successful attacks…
Pendiente de análisisAlta (8.1)0.43%—Oracle Demand Signal RepositoryAIOracle E-business SuiteAI15/9/202621/9/2026
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.…
Pendiente de análisisAlta (8.1)0.35%—Oracle Demand Signal RepositoryAIOracle E-business SuiteAI15/9/202618/9/2026
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.…
Pendiente de análisisAlta (8.1)0.35%—Oracle Demand Signal RepositoryAIOracle E-business SuiteAI15/9/202618/9/2026
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.…
Pendiente de análisisAlta (8.1)0.35%—Oracle Demand Signal RepositoryAIOracle E-business SuiteAI15/9/202618/9/2026
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.…
Pendiente de análisisAlta (7.3)0.13%—Redhat Leapp-repositoryAIOracle MysqlAI15/9/202616/9/2026
A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that…
AnalizadaBaja (3.5)0.58%—Microsoft Sharepoint Server8/9/20269/9/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalizadaAlta (7.5)0.51%—Microsoft Sharepoint Server8/9/20269/9/2026
Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Sharepoint Server8/9/20269/9/2026
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.99%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (5.4)0.40%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (7.7)0.84%—Microsoft Sharepoint Server8/9/20269/9/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalizadaMedia (6.5)1.00%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalizadaMedia (4.8)0.40%—Microsoft Sharepoint Server8/9/202610/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Sharepoint Server8/9/20269/9/2026
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.91%—Microsoft Sharepoint Server8/9/20269/9/2026
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (5.4)0.45%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (6.5)1.00%—Microsoft Sharepoint Server8/9/20269/9/2026
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalizadaMedia (5.4)0.45%—Microsoft Sharepoint Server8/9/202610/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.